WhatsApp Patches Privacy Flaw in ‘View Once’ Feature After Zengo Discovery

Privacy flaw exposing user status updates to strangers remains unresolved despite being reported months ago

  • WhatsApp has fixed a security flaw in its View Once feature that allowed unauthorized access to disappearing media.
  • Crypto wallet startup Zengo discovered the vulnerability in August 2023 through their web app research.
  • The initial patch by WhatsApp did not fully resolve the security issue.
  • Meta’s latest update prevents unauthorized devices from accessing View Once messages.
  • Security researchers indicate potential remaining vulnerabilities in sender devices.

WhatsApp Patches Major Privacy Vulnerability in Disappearing Media Feature

- Advertisement -

Meta’s messaging platform WhatsApp has implemented a comprehensive fix for a security vulnerability in its View Once feature, addressing a flaw first identified by cryptocurrency wallet provider Zengo in August 2023. The patch comes after months of security concerns about the privacy of supposedly self-destructing media content.

Technical Vulnerability Details

The security flaw, documented by Zengo’s research team, revealed that WhatsApp’s View Once feature could be bypassed through the platform’s web application. The feature, designed to automatically delete media files after a single viewing, failed to enforce restrictions at the API server level.

Zengo’s co-founder Tal Be’ery explained: "When we looked into the implementation details we were very surprised to find that although ‘View Once’ is meant to be limited to platforms in which the app can control its displayed content and prevent other processes from abusing it, it is not enforced by WhatsApp’s API server."

Remaining Security Considerations

While the new update represents a significant improvement, Be’ery notes persistent security concerns:

  • Sender devices still retain access to View Once messages
  • Potential forensic extraction risks remain
  • Increased attack surface due to message availability on multiple sender devices

The discovery emerged from Zengo’s research into messaging platforms as part of their development of Multi-Party Computation (MPC) cryptocurrency wallet technology. The company’s technical team constructed an unofficial WhatsApp client based on open-source web client implementation to demonstrate the vulnerability.

Meta’s response included an initial patch that proved insufficient, followed by the current more comprehensive solution that prevents unauthorized devices from accessing View Once messages, though security experts maintain that additional improvements could further enhance user privacy.

- Advertisement -

✅ Follow BITNEWSBOT on Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

Stay in the Loop

Get exclusive crypto insights, breaking news, and market analysis delivered straight to your inbox. No fluff, just facts.

    1 Email per day. Unsubscribe at any time.

    - Advertisement -

    Latest News

    GreedyBear Malware Uses Fake Firefox Wallet Extensions to Steal $1M

    A campaign using over 150 fake Firefox extensions stole more than $1 million in...

    Ripple XRP Soars 11% as SEC Case Ends, Trump 401k Order Lifts Hopes

    XRP price surged 11%, reaching $3.34 amid rising trader interest. Dismissal of appeals by Ripple...

    Trump Executive Order Opens 401(k) Accounts to Cryptocurrency Investments

    President Donald Trump signed an executive order on August 7 allowing Americans to use...

    Block Adds 108 BTC in Q2, Bitcoin Holdings Now Worth $1.15B

    Block added 108 Bitcoin (BTC) to its holdings in the second quarter of 2025,...

    Mystery Creator Nets $5M Launching Hundreds of Memecoins Daily

    One memecoin creator has launched hundreds of tokens daily since January.The creator has made...

    Must Read

    What Is the Dencun Upgrade for Ethereum?

    The Dencun Upgrade for Ethereum is poised to revolutionize the blockchain landscape, offering improved scalability, efficiency, and groundbreaking features. Set to launch at the...